CVE-2026-10160: TRENDnet TEW-432BRP formSetEnableWizard stack-based overflow
A security vulnerability has been detected in TRENDnet TEW-432BRP 3.10B20. Affected by this issue is the function formSetEnableWizard of the file /goform/formSetEnableWizard. Such manipulation of the argument startwizard leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities." This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10160?
The severity of CVE-2026-10160 is rated high with a CVSS score of 8.8.
How does the CVE-2026-10160 vulnerability occur?
CVE-2026-10160 occurs due to a stack-based buffer overflow in the function formSetEnableWizard when manipulated improperly.
What products are affected by CVE-2026-10160?
The TRENDnet TEW-432BRP model, specifically version 3.10B20, is affected by CVE-2026-10160.
Can CVE-2026-10160 be exploited remotely?
Yes, the vulnerability CVE-2026-10160 can be exploited remotely.
What type of attack does CVE-2026-10160 involve?
CVE-2026-10160 involves a stack-based buffer overflow attack.